CVE-2017-5075 describes an inappropriate implementation in Content Security Policy (CSP) reporting within Google Chrome's Blink engine, affecting versions prior to 59.0.3071.86 on Linux, Windows, and Mac, and 59.0.3071.92 on Android. This vulnerability allowed a remote attacker to obtain URL fragment values through a crafted HTML page. With a CVSS score of 4.3 (Medium), this vulnerability has a low impact on confidentiality and requires user interaction (UI:R) for exploitation, but has low attack complexity (AC:L) and no authentication required (PR:N). The potential impact is limited to information disclosure (C:L) without affecting integrity or availability. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage are minimal, indicating low public attention to this specific vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 59.0.3071.86CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 59.0.3071.92CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.